A Research on Shilling Attacks Based on Variational graph auto-encoders for Improving the Robustness of Recommendation Systems
Qianlong Lu, Maoting Gao · 2024
As personalized recommendation techniques continue to evolve and be applied, recommendation systems face a plethora of malicious attacks. In order to defend against potential malicious attacks, enhance the robustness of recommendation systems, and strengthen their ability to withstand attacks, it is necessary to propose a method based on Variational Graph Auto-encoders (VGAE) for generating shilling attacks. This method improves the VGAE model, models user profiles, and generates reconstructed user profiles that conform to the original rating patterns. By utilizing spectral clustering, users are selected from the original dataset as templates in a dispersed manner according to a certain attack scale. These templates are then matched with the most similar fake users in the reconstructed user profiles. Within these fake user profiles, ratings for the most popular items in each category and target item ratings are inserted. Finally, fake user profiles are generated and injected into the recommendation system to broadly promote target items to users of the system. Experimental results on the MovieLens 100k and 1M datasets demonstrate that this new method exhibits more stable attack performance and stronger detection evasion capabilities compared to traditional attack strategies, thereby better exposing existing issues within recommendation systems.